Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

171–174 of 174 posts

Re: About the “Security Issue” on VLC

#171

Earlier quoted context omitted.

CVSS is an insane rating system made for a simpler time by antiquated practices which doesn't account for many factors either well if at all. Hover your mouse over each button https://www.first.org/cvss/calculator/3.0 . There's Attack complexity 'low' and 'high', for instance. You're either a script kiddie or have a two billion dollar exploitation budget and all the human resources you need, but nothing in between.

I will wear my vendor hat here for a moment, AC not about the attacker, but the configuration of the component being assessed.

It's both:

"A successful attack depends on conditions beyond the attacker's control. That is, a successful attack cannot be accomplished at will, but requires the attacker to invest in some measurable amount of effort in preparation or execution against the vulnerable component before a successful attack can be expected. For example, a successful attack may require the attacker: to perform target-specific reconnaissance; to prepare the target environment to improve exploit reliability; or to inject herself into the logical network path between the target and the resource requested by the victim in order to read and/or modify network communications (e.g. a man in the middle attack)."

But you could also argue 'Attack complexity' of any exploit which has per-os/arch exploits requires reconnaissance. There, I just boxed MS08-67 (which is arch-specific, iirc) as 'Attack Complexity: High' with pretty much any theoretical crypto attack which would cost billions to exploit :)

Lets not forget CVSS doesn't assess likelihood or business impact well (or at all) either. Your org is far more likely to get rekt if you do not enforce application whitelisting, compared to an intranet-exposed drupalgeddon vulnerability.

Re: About the “Security Issue” on VLC

#172
post #96

Earlier quoted context omitted.

Everybody, including researchers, has a duty to publish things responsibly and if necessary, withhold the publication. Despite the economical incentives, the moral responsibility is to research and harden systems, not to publish whatever and build a resume. You can't just publish information harmful to public and say "well I'm a researcher, so I can do anything I want". Publishing instructions to bypass important sec…

Does this universal duty to work for free only concern security research? >You can't just publish information harmful to public It’s simply ridiculous to describe full disclosure like that.

I've heard some interesting arguments about publicly dropping 0days to make organisations pull their heads in - Places like Microsoft which historically weren't -great- at security 'deserved' it. I'm not saying that argument is right or wrong, but it was interesting nonetheless.

But dropping a 0day irresponsibly can lead to actual impact - what happens if a good person is persecuted, or executed because of the information you disclosed publicly? What about a hundred. Or a thousand?

Re: About the “Security Issue” on VLC

#173
post #170

Earlier quoted context omitted.

The actual packages are from Debian, and Debian keeps them updated. Debian stretch (2017) is vulnerable, buster is not. Ubuntu 18.04 LTS is based on buster ( https://askubuntu.com/questions/445487/what-debian-version-a... ) so compatibility isn't the problem. Judging from bugs like https://bugs.launchpad.net/ubuntu/+source/libebml/+bug/14120... the problem is just that nobody at Ubuntu is responsible for keeping it u…

The package in Debian was updated four days before Ubuntu 18.04 was released. That's why the update didn't make 18.04 "automatically". Since then, both Debian and Ubuntu have acted the same: not knowing about the vulnerability, neither updated their [release] packages. Buster happened to have been updated before it was frozen for release. Stretch was not, and neither was 18.04. > tl;dr Avoid Ubuntu LTS because they d…

> By your logic, you should also avoid Debian then

It's true, I was looking at Debian testing & sid as possibilities but apparently they can't handle mass rebuilds very well and the recommended workaround is to just not update. So rolling distros only for me. (current NixOS)

Re: About the “Security Issue” on VLC

#174
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

Yep, me too -- thanks so much for the great VLC player, keep up the great work!
Post reply on HN